Recital 74
Digital Operational Resilience Act · UE 2022/2554
| (74) | Such contractual arrangements should also provide for dedicated exit strategies to enable, in particular, mandatory transition periods during which ICT third-party service providers should continue providing the relevant services with a view to reducing the risk of disruptions at the level of the financial entity, or to allow the latter effectively to switch to the use of other ICT third-party service providers or, alternatively, to change to in-house solutions, consistent with the complexity of the provided ICT service. Moreover, financial entities within the scope of Directive 2014/59/EU should ensure that the relevant contracts for ICT services are robust and fully enforceable in the event of resolution of those financial entities. Therefore, in line with the expectations of the resolution authorities, those financial entities should ensure that the relevant contracts for ICT services are resolution resilient. As long as they continue meeting their payment obligations, those financial entities should ensure, among other requirements, that the relevant contracts for ICT services contain clauses for non-termination, non-suspension and non-modification on grounds of restructuring or resolution. |
In Luxembourg, the Banque centrale du Luxembourg acts as national resolution authority alongside the Single Resolution Board (SRB) for significant institutions. The Law of 18 December 2015 on the resolution of credit institutions and certain investment firms transposes BRRD and requires critical ICT contracts to be resolution resilient, in direct alignment with DORA Recital 74. The CSSF verifies this articulation during its ICT governance inspections.
Luxgap practice: we systematically map your contractual clauses against combined CSSF (Circular 22/806 on ICT outsourcing) and BCL resolution expectations, to prevent a non-EU cloud provider from invoking its home jurisdiction to escape non-termination clauses.